Impact
This vulnerability is an out‑of‑bounds write in the Intel Slim Bootloader firmware. Because the flaw is triggered by a local privileged user executing a low‑complexity attack, it can potentially lead to a failure of the boot process, effectively denying system availability. The CVE description states a low availability impact and no effect on confidentiality or integrity, which means that an attacker would likely aim to stop the system from booting rather than tampering with data.
Affected Systems
Intel devices that ship with the Slim Bootloader firmware are affected. No particular firmware revisions are listed in the advisory, so all current firmware deployments should be considered vulnerable until a vendor fix is applied.
Risk and Exploitability
The CVSS score of 1.8 indicates a low severity, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Since the exploitation requires local privileged access, the attack surface is limited to environments where such privileges exist. Overall, the risk remains low, though a denial of service at boot time could disrupt mission‑critical operations.
OpenCVE Enrichment